Risks when businesses violate employee privacy

Insights
Risks when businesses violate employee privacy
Posted on: 24/11/2025

    The breach of the General Data Protection Regulations (GDPR) at the H&M Service Center in Nuremberg, Germany is an important legal "case study" on the privacy of workers at enterprises. Perhaps this will be an issue that causes controversy and even frequent disputes in the near future in Vietnam, when the Law on Personal Data Protection 2025 will take effect from January 1, 2026.

     

     

    1. Background of the case

    The incident revolves around H&M Nuremberg's illegal employee surveillance behavior that lasted at least five years (from 2014 to 2019). The Center's management collected and stored voice recordings and meticulous notes about the private lives and sensitive health information of several hundred employees through internal meetings.

    On October 1, 2020, the Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI) issued a €35 million fine against H&M Hennes & Mauritz Online Shop A.B. & Co. KG, a subsidiary of Swedish fast-fashion retail group H&M (collectively, H&M"),  operating in Germany and had sales of about 3 billion euros in the country in the previous year. The decision is based on a violation of Articles 5 and 6 of the GDPR, which considers this an act of unlawful data processing and a serious violation of the civil rights of employees. At the time, it was the second largest fine imposed in Europe.

    In this case, H&M was determined to hold both roles as a Data Controller Employee Data Processor (data subject). Holding this dual role represents the company's comprehensive and undeniable legal responsibility. When a company is both a controller (determining the purpose of collection) and a processor (deciding how it is stored and protected), any breach regarding the lawfulness of data processing that is a core element of the breach will directly place the burden of proving compliance on the shoulders of the company.

    2. European Legal Framework for Labour Data

    The GDPR provides a robust data protection framework, and in the labor context, personal data is highly sensitive due to the inherently asymmetrical power relationship between employers and employees.

    Article 88 of the GDPR recognizes the right of EU Member States to establish more specific rules on data protection in the field of labor. National rules must include specific and appropriate measures to protect human dignity, legitimate interests and fundamental rights of data subjects, in particular with regard to transparency of processing and monitoring systems in the workplace[1].

    However, the ruling regarding employment agreements under Article 88 also specifies that the regulatory powers of employers and labor councils do not include any discretion to apply the requirements of the necessity of the GDPR in a less stringent manner or to exempt them. This asserts that for reasons of efficiency or simplicity, internal agreements must not be compromised in a way that unduly compromises the goal of ensuring a high level of protection for employees under the GDPR. The H&M case clearly illustrates this limitation, showing that even with internal policies, they must still strictly adhere to the core principles of the GDPR.

    3. Why H&M was severely sanctioned

    Clear and serious violations

    H&M management collected voice recordings and detailed notes of many employees through personal meetings called "Welcome Back Talks." These meetings take place after an employee's absence, such as holidays or sick leave. In addition, management also gathers information through one-on-one meetings and even "lobby conversations".

    These notes are permanently stored by H&M on a local network drive. Data analysis shows that the scope of the violation is enormous. The document is about 60GB in size. Even more seriously, as many as "50 other managers" in H&M's vast corporate system have access to at least part of this personal and sensitive information. The fact that this activity lasted for 5 years and involved a large number of managers showed that this behavior was not the fault of an individual, but rather a cultural and systemic problem that was implemented or established informally in the HR management process. "Welcome Back Talks" meetings have been transformed from an absence management tool into a monitoring tool, which is used to create detailed records to support labor decisions, which exacerbates the level of invasion of workers' privacy.

    A lot of sensitive information of employees is collected and processed over a long period of time

    The severity of the breach is directly proportional to the invasiveness of the data collected. The information stored includes a variety of sensitive personal data:

    Sensitive health information: Conversations include sensitive health information, symptoms of illness, and diagnoses for sick leave.

    Personal and Religious Life Information: Notes contain details about employees' personal lives, including family disputes, religious beliefs, and vacation experiences.

    This highly personal information, in particular health and religious data (which falls under Article 9 GDPR Special Data), has been processed to "create a detailed profile" of employees. These records are then used in conjunction with meticulous performance reviews to create "employee profiles for measures and decisions in industrial relations". This combination of private life research and ongoing recordings constituted "particularly intensive intervention" on the well-being of those affected.

     

     

    H&M does not detect violations on its own

    It is worth noting that this serious incident was not discovered through internal audits or employee reports. Instead, the breach was only made public by accident in October 2019, when a technical configuration error made the data accessible throughout the company for several hours.

    This technical incident is considered a secondary violation, while illegal data collection that lasts for 5 years is the primary violation. Press reports after the incident alerted HmbBfDI, which immediately ordered the network drive to be "frozen" and collect 60GB of content to conduct an investigation. The main breach continued indefinitely and was only exposed due to an unrelated security failure that showed a complete absence of effective internal control and accountability mechanisms. This shows that H&M has failed not only to comply with the core principles of the purpose of data processing, but also to implement appropriate technical security measures to protect the data that has been collected. A requirement not only of the European Union but also of many countries for the protection of workers' personal data.

    4. H&M's Sanctioning Decision and Response

    Strict fines in the field of labor

    As mentioned above, HmbBfDI imposed an exact fine of €35,258,707.95. The regulator argued that this fine was necessary because H&M's conduct was not only illegal data processing but also a "serious violation of the civil rights" of its employees.

    The application of heavy fines is determined based on a number of factors: the severity of the behavior, the duration of the violation (5 years), the large number of employees affected (several hundred people), and the special invasive nature of the data collected (health,  religion). The fine is considered "proportional" to the extent of H&M's violation.

    The main purpose of this €35 million fine, as announced by HmbBfDI, is to deter companies from violating employee privacy in the future, which applies to both H&M and other global corporations. The fine sends a clear message that the EU's personal data protection authorities will use their powers to protect workers' fundamental rights.

    At the time of publication, the €35 million fine was the second largest penalty issued under the GDPR in Europe and the largest for an industrial relations-related breach since the GDPR came into force in May 2018. The case has set an important standard for how employee data is handled.

    H&M's Consistent and Effective Response

    H&M's response to the case was a factor that was positively reviewed by HmbBfDI, contributing to the maximum mitigation of legal consequences. The company has demonstrated an unprecedented and clear recognition of corporate responsibility.

    Shortly after the breach was discovered, H&M quickly issued a press release claiming "full responsibility" and sending an "unconditional apology" to affected employees. The company has provided significant financial compensation to those affected.

    This prompt and goodwill cooperation, including the transparent provision of all necessary information, has been highly appreciated by HmbBfDI. Employee compensation is a step that goes beyond the minimum legal requirement, shows goodwill, and helps the company minimize reputational damage.

    In addition, to ensure future GDPR compliance and address the root cause of the breach, H&M soon implemented a series of far-reaching improvements such as:

    1. Make changes to the management department at the Service Center;
    2. Provide additional training on data protection and privacy regulations;
    3. Establishes a new role as the Data Protection Coordinator, who is responsible for auditing and continuously improving data privacy;
    4. Provides monthly data protection status updates;
    5. Increased protection for whistleblowers;
    6. Improve data cleansing and other IT solutions to support compliance.

    The H&M Nuremberg incident is a valuable lesson, showing the risks of misuse of employee data collection and processing. The record fine of €35 million not only reflects the seriousness of the violation, but also a strong policy statement from HmbBfDI, confirming that employee privacy is a fundamental right that should be protected at the highest level. This is not only a lesson for European businesses, multinational enterprises, but even Vietnamese businesses may completely face these risks in the near future. Therefore, it is essential to prepare and develop appropriate strategies for collecting and processing legal worker data.